nerdexam
Isaca

CRISC · Question #310

An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in…

The correct answer is A. Risk owner. When a documented and accepted risk materializes, the designated risk owner is accountable for the resulting losses as they are responsible for managing and accepting that specific risk.

Submitted by kim_seoul· Apr 18, 2026Governance

Question

An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in the risk register and accepted. Who should be accountable for any related losses to the organization?

Options

  • ARisk owner
  • BIT risk manager
  • CServer administrator
  • DRisk practitioner

How the community answered

(31 responses)
  • A
    84% (26)
  • B
    3% (1)
  • C
    3% (1)
  • D
    10% (3)

Why each option

When a documented and accepted risk materializes, the designated risk owner is accountable for the resulting losses as they are responsible for managing and accepting that specific risk.

ARisk ownerCorrect

The risk owner is the individual or entity assigned responsibility for managing a specific risk, including accepting it. If a risk has been formally documented and accepted, the risk owner bears accountability for the consequences should that risk materialize, as they have either implicitly or explicitly agreed to the potential impact.

BIT risk manager

An IT risk manager facilitates the overall risk management process, but they are typically not the ultimate accountable party for specific accepted risks; that falls to the designated risk owner.

CServer administrator

A Server administrator is responsible for the technical implementation and maintenance, including patching, but if the risk of poor patch management was accepted by a higher authority (the risk owner), the ultimate accountability for losses lies with the risk owner, not the implementer.

DRisk practitioner

A Risk practitioner identifies, assesses, and reports on risks, but they do not typically own or accept risks; their role is advisory and facilitative within the risk management framework.

Concept tested: Risk ownership accountability

Source: https://www.isaca.org/resources/isaca-journal/issues/2023/volume-3/risk-ownership-in-the-digital-age

Topics

#Risk ownership#Accountability#Risk acceptance#Risk management roles

Community Discussion

No community discussion yet for this question.

Full CRISC Practice